See who can reach cluster-admin — and which CVE to fix first.
Attack paths, image CVEs, misconfigurations and compliance scorecards, ranked in the same queue as reliability and upgrade risk. The agent that finds them is read-only and never reads a secret value.
one helm install · get, list, watch only · first findings in minutes
Security posture
One ranking for security and reliability.
Attack paths
Who can reach cluster-admin, node root, every Secret or a cloud role, and through which grants. 18 rules cover RBAC bindings, ServiceAccount tokens, pod escalation and cloud identity.
Image CVE scanning
Every running image is scanned, showing the CVE, package, fixed version and severity for each workload. The scanner runs as an ephemeral Job in your cluster.
Misconfiguration posture
Privileged containers, running as root, hostPath mounts and missing security context add up to a posture score.
Compliance scorecards
CIS Kubernetes, CIS EKS and NSA, with pass or fail per control and the failing resources named.
Unified score and fleet ranking
One security number per cluster, with the fleet ordered by criticality.
Fix-first across axes
A critical CVE on the workload that also blocks your 1.31 upgrade is ranked first, because one change clears both. Rescan on demand and work from a prioritized remediation drawer.
A security review your team will approve
The trust posture is the product.
Read-only RBAC
Only get, list and watch. No mutating verbs, no kubeconfig handover, no inbound access. Uninstall is one command.
Secret names only
The inventory records that a secret exists. Values are never read or transmitted.
Scanning stays inside
Scan Jobs run as ephemeral pods in your cluster. Images and pull secrets never leave it.
Multi-tenant with roles
Everything is scoped to your org, with Owner, Admin, Platform Engineer, Developer and Viewer roles.
Redaction on every AI path
Evidence is scrubbed of secrets before it reaches any model.
Its own findings, labelled
The Runtimez agent's own attack-path findings are tagged as expected, each with the chart value that removes it.
How it compares
They rank CVEs by severity. Runtimez ranks them by which fix also unblocks your upgrade.
One agent, the rest of the platform
Every product runs off the same read-only sweep and feeds the same ranked queue.
See it on your own cluster in under an hour.
Free for your first cluster. Read-only by default. Uninstall is one helm command.
